FomoPeek Crypto Tracker Hid Malware That Could Steal iPhone Wallet Keys

Hidden inside versions 1.1 and 1.2, the code targeted iOS 12 through 26 and ran silently for eight days before removal

Al Landes Avatar
Al Landes Avatar

By

Image: Apple

Key Takeaways

Key Takeaways

  • FomoPeek hid kernel-exploitation modules in official App Store versions 1.1 and 1.2.
  • Malware could escape iOS sandbox and steal Keychain keys, seed phrases, and passwords.
  • Deleting FomoPeek is insufficient; transfer funds to a new wallet on a clean device.

This one came through the official App Store, not a sideload or a jailbreak workaround. A joint investigation by SlowMist and OKX Security found that FomoPeek, a cryptocurrency market-tracking app for iPhone, contained hidden malicious code in versions 1.1 and 1.2 reportedly capable of exploiting the iOS kernel, escaping the app sandbox, and decrypting Keychain data stored on your device. SlowMist says its team analyzed historical IPAs obtained directly from the App Store, confirming the threat was not limited to unofficial or re-signed builds. The malicious versions were reportedly live for eight days before a clean release replaced them.

What FomoPeek Actually Did

Two undisclosed modules hidden inside the official packages gave the app capabilities far beyond anything a crypto price tracker needs.

Two hidden modules, named apptrace and libapptracecore, were embedded inside the App Store packages for versions 1.1 and 1.2, according to SlowMist’s analysis. Those modules had nothing to do with tracking cryptocurrency prices.

SlowMist reported that the kernel-exploitation framework supported eight attack methods, selecting the appropriate exploit based on your specific device model and iOS version. According to the researchers, the affected range covers iOS 12.0 through 18.7 and iOS 26.0 through 26.1.

Sandbox escape is the detail that matters most. iOS normally keeps each app isolated in its own container, limiting its access to files and data belonging to other apps. These modules reportedly broke that barrier. The malicious code could potentially access Keychain-stored passwords, seed phrases, private keys, and data from other apps on the same device, according to SlowMist’s findings.

SlowMist’s version-history analysis places the malicious code’s introduction on September 9, its retention in version 1.2 released September 12, and its reported removal in version 1.3 on September 17.

Why Deleting the App Is Not Enough

SlowMist warned the attack functions could run on a timer, operating in the background without any action from you.

SlowMist warned that the attack functions could execute automatically at regular intervals, meaning the malware may have operated quietly even if you never actively opened the app after installing it. Any sensitive data accessible on that device during that window should be treated as potentially compromised, based on the reported sandbox-escape and Keychain-access capabilities.

Deleting FomoPeek cannot recall information that may already have been extracted. Think of it like food poisoning: removing the dish from the table does nothing about what already happened.

What to Do Now

If FomoPeek 1.1 or 1.2 was ever on your iPhone, the response needs to go further than a simple delete.

If FomoPeek 1.1 or 1.2 was ever on your iPhone, stop using that device for sensitive information immediately. Do not enter or view seed phrases, private keys, or exchange credentials on it.

On a separate, clean device that never had FomoPeek installed, generate a completely new wallet with a fresh seed phrase. Transfer any cryptocurrency from potentially exposed addresses to that new wallet.

Delete FomoPeek from the affected device and install the latest available iOS security update. Updating cannot recover data that may already have left the device, though it may address underlying vulnerabilities the malware reportedly targeted. No Apple advisory confirming the specific patch was available at the time of publication.

Rotate every credential accessible through that iPhone. That includes Keychain passwords, Apple Notes, browser autofill, messaging apps, and any exchange or wallet service you accessed. Review affected wallet addresses for unauthorized transfers and revoke any token approvals where applicable.

For high-value wallets or accounts, the safest path is a complete device erase followed by a clean reinstall from trusted sources, without restoring potentially compromised secrets. For broader guidance on keeping your device secure, see how to stay safe against common mobile threats.

The Bigger Picture

This incident illustrates the gap between marketplace provenance and actual device-level security.

An App Store listing is a distribution channel, not a security guarantee. Anyone holding meaningful cryptocurrency on a general-purpose smartphone should seriously consider a dedicated hardware wallet or an isolated signing device, keeping seed phrases off a phone that also runs dozens of third-party apps.

Share this

At Gadget Review, our guides, reviews, and news are driven by thorough human expertise and use our Trust Rating system and the True Score. AI assists in refining our editorial process, ensuring that every article is engaging, clear and succinct. See how we write our content here →